Configuring SAML SSO with UltiPro and PingOne for Enterprise
Learn how to enable UltiPro sign-on from the PingOne for Enterprise console (IdP-initiated sign-on) and direct UltiPro sign-on using PingOne for Enterprise (SP-initiated sign-on).
Before you begin
-
Link PingOne for Enterprise to an identity repository containing the users requiring application access.
-
Populate UltiPro with at least one user to test access.
-
You must have administrative access to PingOne for Enterprise.
Add the UltiPro application to PingOne for Enterprise
-
Sign on to PingOne for Enterprise and go to Applications → My Applications.
-
On the SAML tab, click Add Application.
-
Enter
UltiPro
as the application name. -
Enter a suitable description.
-
For the category, select Human Resources.
-
Click Continue to Next Step.
-
Set Assertion Consumer Service (ACS) to
https://placeholder
and set Entity ID toplaceholder
.You’ll update these values later.
-
Click Continue to Next Step.
-
Click Add new attribute.
-
Add the SAML_SUBJECT attribute and map it to the value required by UltiPro.
-
Click Continue to Next Step.
-
Click Add for all user groups that should have access to UltiPro.
-
Click Continue to Next Step.
-
Download the PingOne for Enterprise signing certificate and metadata.
-
Click Finish.
Add the PingOne for Enterprise connection to UltiPro
-
Contact UltiPro Customer Support and request that SAML 2 be enabled for your organization.
-
Provide them with the downloaded PingOne for Enterprise signing certificate and metadata.
-
Request their ACS URL and EntityID values.
Complete the UltiPro PingOne for Enterprise setup in UltiPro
-
Continue editing the UltiPro entry in PingOne for Enterprise for Enterprise.
If the session has timed out, complete the initial steps to the point of clicking Setup.
-
Click Continue to Next Step.
-
Set the ACS URL to the UltiPro ACS URL value.
-
Set the Entity ID to the UltiPro Entity ID value.
-
Click Continue to Next Step until you reach the final page, then click Finish.
Test the PingOne for Enterprise IdP-initiated SSO integration
-
Go to your Ping desktop as a user with UltiPro access.
To find the Ping desktop URL in the Admin console, go to Setup → Dock → PingOne Dock URL.
-
Complete the PingOne for Enterprise authentication.
You’re redirected to your UltiPro application.